OpenAI Agent SDK
PassAudited by VirusTotal on May 15, 2026.
Findings (1)
The skill bundle contains a critical Remote Code Execution (RCE) vulnerability in 'examples/tools_example.py' and 'SKILL.md'. The 'calculate' tool uses the Python 'eval()' function to process user-provided strings without any sanitization, which allows for arbitrary code execution. While this appears to be a poorly implemented example rather than intentional malware, the inclusion of such a dangerous pattern in a 'Best Practices' section is highly risky.
